pepe-unchained[.]xyz
“Pepe Unchained | Pepe's Own Layer 2 Blockchain”
Analysis of pepe-unchained.xyz indicates this domain was actively involved in a crypto scam operation, as classified by multiple security vendors. The domain was registered on November 17, 2025, through NiceNIC International Group Co., Limited, and resolved to IP 66.235.200.251, hosted on Cloudflare's network (AS13335) in the United States. No SSL certificate was present, increasing the risk of unencrypted data transmission. The page title, 'Pepe Unchained | Pepe's Own Layer 2 Blockchain,' suggests an attempt to impersonate or promote a fraudulent blockchain project, aligning with the scam type identified in threat intelligence feeds.
The domain appears on two security blocklists and is flagged by 11 of 95 security vendors on VirusTotal, with additional blocking by PhishDestroy and ScamSniffer. Gridinsoft assigned a trust score of 0/100, further corroborating its malicious classification. Nameservers hgns1.hostgator.com and hgns2.hostgator.com were associated with the domain, though this infrastructure may have been reused or compromised. As of the report date, the domain is offline, but defenders should treat any reactivation as high-risk.
Defenders are advised to block the domain at the DNS and network level, monitor for related infrastructure (e.g., similar domains, shared IPs, or nameservers), and review logs for connections to 66.235.200.251. Given the crypto scam classification, alert users to potential financial fraud risks if the domain resurfaces. The exact content and functionality of the site remain unanalyzed, but the available evidence supports its designation as malicious.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 03:15:52 UTC
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive